US States Lag in Quantum Encryption Preparedness as “Q-Day” Looms
US states are largely unprepared for "Q-Day," the anticipated future date when advanced quantum computers could break current encryption methods, posing significant cybersecurity risks to sensitive data. While the federal government is mandating a transition to post-quantum cryptography (PQC) for…

Detroit, MI, September 10, 2026 — A significant cybersecurity vulnerability is emerging across the United States as most states are inadequately prepared for “Q-Day,” the projected future point at which powerful quantum computers could compromise current encryption standards. This unpreparedness poses substantial risks to sensitive data held by state governments and critical infrastructure.
The advent of advanced quantum computing capabilities, often referred to as “Q-Day,” is anticipated to render many of today’s widely used cryptographic algorithms obsolete. This would leave vast amounts of digital information, including personal data, financial records, and national security secrets, vulnerable to decryption by adversaries.
While the federal government has begun implementing mandates for its agencies to transition to post-quantum cryptography (PQC)—new encryption methods designed to resist quantum attacks—the preparedness at the state level appears critically low. Reports indicate that a majority of U.S. states lack comprehensive active plans, dedicated resources, or clear guidance necessary to implement these crucial cryptographic upgrades.
The implications of this gap in preparedness are far-reaching. Critical infrastructure, such as power grids, water systems, and transportation networks, often relies on the same encryption methods that could be broken by quantum computers. Without a timely migration to PQC, these systems could become targets for sophisticated cyberattacks, potentially leading to widespread disruption and security breaches.
Furthermore, state governments manage immense volumes of sensitive citizen information, including personally identifiable information (PII), health records, and financial details. A failure to secure this data against future quantum threats could result in mass data breaches, identity theft, and a severe erosion of public trust. The contractor responsible for assessing state preparedness was not explicitly named in available information, nor were specific timelines for state-level PQC adoption detailed.
The transition to PQC is a complex undertaking, requiring significant investment in new technologies, expertise, and systemic overhauls. Experts have long warned of the need for proactive measures to avoid a post-quantum cryptographic crisis. The current state of readiness suggests many states are not yet prioritizing this looming threat, leaving their digital assets and the data of millions of residents exposed to future quantum cyber risks.
Story summarized from the original created by Grant Johnson, Emily Mosier and Gaige Davila/Howard Center for Investigative Journalism ASU on www.wxyz.com, see more information here.
